I think ethereal can decode DCERPC carried ontop of SMBreadX just fine. Make sure you have DCERPC reassembly enabled : DCERPC/Desegment all DCEoverTCP (also includes SMB transport) SMB/Reassemble SMB Transaction Payload SMB/Reassemble DCERPC over SMB You probably also want to enable NBSS/Reassemble NBSS over TCP and TCP/Allow subdissector to desegment TCP streams ----- Original Message ----- From: "Devin Heitmueller" Subject: [Ethereal-dev] Support SMBreadX in SAMR calls > Hello, > > I've been doing some work with SAMR calls using Ethereal, and I am > seeing that Ethereal is incapable of dissecting the trace if the PDU is > large enough to require the use of SMBreadX and SMBwriteX. > > Has anyone investigated being able to handle output represented in a > SMBreadX request? Has anyone determined that this is not practical or > technically feasible? > > Thanks,
Powered by MHonArc 2.6.10